$ the-wire · showcase
Shopify CLI groups App Security findings and guards agent scans
By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology
Shopify CLI made its App Security check quieter in the terminal and harder to accidentally overwrite, adding config support, rule-level grouping, and a scan guard that preserves agent findings.
Group repeated App Security findings in human-readable output Shopify/cli
The human-readable report now collapses repeated findings by rule, optional pattern, and severity, while JSON, traces, scoring, and check counts still keep every occurrence. Expect far less scrolling; expect nothing to change for consumers of the structured output.
Protect App security agent findings from new scans Shopify/cli
New scans are refused when agent findings or compiled review results already exist, so the deterministic check can no longer replace that work. Discarding the current review and starting over now requires the new --clean flag.
Harden app security scan safeguards Shopify/cli
Hardening on the same safeguard: --clean must be given explicitly and inherited environment values are ignored, and clean compilation is rejected before any artifacts are written. Command-boundary tests cover compiled-trace and findings protection.
Merge pull request #8578 from Shopify/joshlarson/app-doctor-config-flag Shopify/cli
The App Security Check now accepts --config, so scan configuration can be pointed at a file instead of relied on ambient defaults.
Merge pull request #8561 from Shopify/joshlarson/app-doctor-group-findings Shopify/cli
The grouping work landed alongside preserving every occurrence, so collapsed terminal output and full finding records no longer trade off against each other.
Action items